Files
telemt/docker-compose-dokploy.yml
T
ali_rajabpour 721b75c687 perf/deploy: optimize hot-path allocs (cut per-session ad_tag allocations), split metrics module, and add ENV config support
Three independent changes bundled here — performance, maintainability, and
deployment DX.

1. Hot-path Allocations (ad_tag caching):
Every middle-relay session was doing a hex::decode of the user's ad_tag (plus a fallback to the global one) on every single connection. That's two string allocations and two hex decodes per session for data that only changes on config reload. Moved the decoding into ProxyConfig load/hot-reload into a precomputed runtime_ad_tags cache (same #[serde(skip)] pattern as runtime_user_auth). The session path now does a single O(1) lookup via config.effective_ad_tag(&user). Falls back to on-demand decode if the cache isn't built (e.g. in tests), so existing behavior is preserved. This eliminates two useless allocations and hex decodes per connection.

2. Metrics Monolith Split(structural refactor):
Broke up the massive 4,200-line `metrics.rs` into a proper `metrics/` directory module (`mod.rs`, `tls_front.rs`, `tests.rs`). I isolated the giant `render_metrics` function into its own `render.rs` file. This was a purely structural move—no locks or function bodies were changed, keeping things build-safe while making the crate significantly easier to navigate. The /metrics endpoint output is byte-identical.

3. GitOps / Dokploy Auto-Deployment Support (deployment DX):
Added `figment` to `Cargo.toml` to seamlessly merge TOML config files with Environment Variables. You can now configure the proxy entirely using `TELEMT_` prefixed ENV variables (e.g., `TELEMT_GENERAL__PORT=443`) without needing to manually mount a physical `config.toml` via Docker volumes. The Dockerfile and compose setups now gracefully handle missing config files by generating an empty placeholder, making stateless auto-deployments on platforms like Dokploy frictionless.
2026-08-03 18:41:24 +04:00

72 lines
2.0 KiB
YAML

# Dokploy-ready compose file.
#
# MTProto is not HTTP, so Traefik (HTTP reverse proxy) cannot route it.
# Dokploy's Traefik is configured with HTTP TLS termination on port 443,
# which conflicts with MTProto's TLS passthrough requirement.
#
# Solution: publish a dedicated port (8443) directly from the container,
# bypassing Traefik entirely for MTProto traffic. Port 443 stays with
# Traefik for other HTTP services on the server.
#
# Set TELEMT_GENERAL__LINKS__PUBLIC_PORT=8443 in your Dokploy env vars
# so generated share links use the correct public port.
#
# Metrics and API endpoints remain internal (expose only, no public ports).
# To access them, use `docker exec` or uncomment the ports below.
#
# All env vars are documented in .env.example. Set them in the Dokploy UI
# environment section, not in this file.
services:
telemt:
image: ghcr.io/telemt/telemt:latest
build:
context: .
target: prod
restart: unless-stopped
ports:
- "${PROXY_PUBLIC_PORT:-8443}:443"
expose:
- "9090"
- "9091"
working_dir: /run/telemt
command: ["/app/config.toml"]
# volumes:
# - ./config:/etc/telemt:rw
tmpfs:
- /run/telemt:rw,mode=1777,size=4m
# env_file passes all vars from Dokploy's .env (TELEMT_*, RUST_LOG, etc.)
# to the container. environment below provides defaults for RUST_LOG.
env_file:
- .env
environment:
- RUST_LOG=${RUST_LOG:-info}
healthcheck:
test: [ "CMD", "/app/telemt", "healthcheck", "/app/config.toml", "--mode", "liveness" ]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
cap_drop:
- ALL
cap_add:
- NET_BIND_SERVICE
read_only: true
security_opt:
- no-new-privileges:true
ulimits:
nofile:
soft: 65536
hard: 262144
logging:
driver: json-file
options:
max-size: "50m"
max-file: "5"
networks:
- dokploy-network
networks:
dokploy-network:
external: true